AI description
CVE-2026-77001 describes an unauthenticated authentication bypass vulnerability found in the "Social Login & Sharing buttons with Analytics By SoClever" WordPress plugin, specifically affecting versions up to and including 1.2.0. This flaw stems from the plugin's failure to perform authentication, authorization, or nonce checks within one of its publicly accessible login handlers. As a result, an unauthenticated attacker can exploit this vulnerability to obtain a valid session as any existing user on the WordPress site. This includes the ability to gain a session as an administrator, potentially without needing to know any account credentials.
- Description
- The Social Login & Sharing buttons with Analytics By SoClever WordPress plugin through 1.2.0 does not perform any authentication, authorisation or nonce checks in one of its publicly accessible login handlers, allowing unauthenticated attackers to obtain a valid session as any existing user, including administrators. In the default case a session as the site's original administrator account is obtained without needing to know any account details at all.
- Source
- contact@wpscan.com
- NVD status
- Received
CVSS 3.1
- Type
- Secondary
- Base score
- 9.8
- Impact score
- 5.9
- Exploitability score
- 3.9
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Severity
- CRITICAL
- 134c704f-9b21-4f2e-91b3-4a467353bcc0
- CWE-287
- Hype score
- Not currently trending
CVE-2026-77001 The Social Login & Sharing buttons with Analytics By SoClever WordPress plugin through 1.2.0 does not perform any authentication, authorisation or nonce checks in one… https://t.co/qB0uNAgdDV
@CVEnew
22 Aug 2026
882 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CVE-2026-77001 Session Hijacking in SoClever WordPress Plugin 1.2.0 Allows Admin Access https://t.co/d3lmEpOZjO
@VulmonFeeds
22 Aug 2026
98 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes